Skip to main content
Gets a list of incident objects that Microsoft Defender XDR (formerly known as 365 Defender) created to track attacks in an organization.
  • Least privileged Microsoft Graph permission to access the action via application: SSecurityIncident.Read.All*.
  • Higher privileged Microsoft Graph permission to access the action via application: SecurityIncident.ReadWrite.All.
External DocumentationTo learn more, visit the Microsoft Defender XDR documentation.

Parameters

Example Output

Workflow Library Example

List Incidents with Microsoft Defender Xdr and Send Results Via Email
Workflow LibraryPreview this Workflow on desktop